Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-4661 |
|
SQL Injection in wordpress (CVE-2026-4661)
SQL injection in wordpress (CVE-2026-4661). Confidential information can be exposed externally.
|
| CVE-2025-5017 |
|
SQL Injection in wordpress (CVE-2025-5017)
SQL injection in wordpress (CVE-2025-5017). Confidential information can be exposed externally.
|
| CVE-2026-15335 |
|
SQL Injection in wordpress (CVE-2026-15335)
SQL injection in wordpress (CVE-2026-15335). Confidential information can be exposed externally.
|
| CVE-2026-15073 |
|
SQL Injection in wordpress (CVE-2026-15073)
SQL injection in wordpress (CVE-2026-15073). Confidential information can be exposed externally.
|
| CVE-2026-15072 |
|
SQL Injection in wordpress (CVE-2026-15072)
SQL injection in wordpress (CVE-2026-15072). Confidential information can be exposed externally.
|
| CVE-2026-13262 |
|
SQL Injection in wordpress (CVE-2026-13262)
SQL injection in wordpress (CVE-2026-13262). Confidential information can be exposed externally.
|
| CVE-2026-47199 |
|
SQL Injection in CVE-2026-47199 (CVE-2026-47199)
SQL injection in CVE-2026-47199 (CVE-2026-47199). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-13242 |
|
SQL Injection in drupal/geolocation (CVE-2026-13242)
SQL injection in drupal/geolocation (CVE-2026-13242). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `3.15.0` or later.
|
| CVE-2026-15081 |
|
SQL Injection in drupal (CVE-2026-15081)
SQL injection in drupal (CVE-2026-15081). Confidential information can be exposed externally.
|
| CVE-2026-57230 |
|
SQL Injection in CVE-2026-57230 (CVE-2026-57230)
SQL injection in CVE-2026-57230 (CVE-2026-57230). Confidential information can be exposed externally.
|
| CVE-2026-11321 |
|
SQL Injection in sqli (CVE-2026-11321)
SQL injection in sqli (CVE-2026-11321). Successful exploitation can lead to full system takeover.
|
| CVE-2026-61461 |
|
SQL Injection in sqli (CVE-2026-61461)
SQL injection in sqli (CVE-2026-61461). Successful exploitation can lead to full system takeover.
|
| CVE-2026-5801 |
|
SQL Injection in sqli (CVE-2026-5801)
SQL injection in sqli (CVE-2026-5801). Successful exploitation can lead to full system takeover.
|
| CVE-2026-53448 |
|
SQL Injection in coturn-project (CVE-2026-53448)
SQL injection in coturn-project (CVE-2026-53448). Successful exploitation can lead to full system takeover.
|
| CVE-2026-2397 |
|
SQL Injection in sqli (CVE-2026-2397)
SQL injection in sqli (CVE-2026-2397). Successful exploitation can lead to full system takeover.
|
| CVE-2026-58492 |
|
SQL Injection in CVE-2026-58492 (CVE-2026-58492)
SQL injection in CVE-2026-58492 (CVE-2026-58492). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-56689 |
|
SQL Injection in sqli (CVE-2026-56689)
SQL injection in sqli (CVE-2026-56689). Confidential information can be exposed externally.
|
| CVE-2026-56690 |
|
SQL Injection in sqli (CVE-2026-56690)
SQL injection in sqli (CVE-2026-56690). Confidential information can be exposed externally.
|
| CVE-2026-58225 |
|
SQL Injection in sqli (CVE-2026-58225)
SQL injection in sqli (CVE-2026-58225). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-13010 |
|
SQL Injection in wordpress (CVE-2026-13010)
SQL injection in wordpress (CVE-2026-13010). Confidential information can be exposed externally.
|
| CVE-2026-12918 |
|
SQL Injection in wordpress (CVE-2026-12918)
SQL injection in wordpress (CVE-2026-12918). Confidential information can be exposed externally.
|
| CVE-2026-15104 |
|
SQL Injection in wordpress (CVE-2026-15104)
SQL injection in wordpress (CVE-2026-15104). Confidential information can be exposed externally.
|
| CVE-2026-14475 |
|
SQL Injection in wordpress (CVE-2026-14475)
SQL injection in wordpress (CVE-2026-14475). Confidential information can be exposed externally.
|
| CVE-2026-15300 |
|
SQL Injection in wordpress (CVE-2026-15300)
SQL injection in wordpress (CVE-2026-15300). Data can be tampered with by attackers. Mitigation: upgrade to `4.5.5` or later.
|
| CVE-2026-15287 |
|
SQL Injection in wordpress (CVE-2026-15287)
SQL injection in wordpress (CVE-2026-15287). Confidential information can be exposed externally.
|
| CVE-2026-15290 |
|
SQL Injection in wordpress (CVE-2026-15290)
SQL injection in wordpress (CVE-2026-15290). Confidential information can be exposed externally.
|
| CVE-2026-15289 |
|
SQL Injection in wordpress (CVE-2026-15289)
SQL injection in wordpress (CVE-2026-15289). Confidential information can be exposed externally.
|
| CVE-2026-59834 |
|
SQL Injection in CVE-2026-59834 (CVE-2026-59834)
SQL injection in CVE-2026-59834 (CVE-2026-59834). Confidential information can be exposed externally. Exploitable via `POST /api/search/fullTextSearchBlock`.
|
| CVE-2026-55208 |
|
SQL Injection in pimcore/studio-backend-bundle (CVE-2026-55208)
SQL injection in pimcore/studio-backend-bundle (CVE-2026-55208). Confidential information can be exposed externally. Exploitable via `POST /pimcore-studio/api/website-settings`. Mitigation: upgrade to `2026.1.6` or later.
|
| CVE-2026-15190 |
|
Vulnerability in sqli (CVE-2026-15190)
vulnerability in sqli (CVE-2026-15190). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-56292 |
|
SQL Injection in sqli (CVE-2026-56292)
SQL injection in sqli (CVE-2026-56292). Confidential information can be exposed externally.
|
| CVE-2026-50644 |
|
SQL Injection in sqli (CVE-2026-50644)
SQL injection in sqli (CVE-2026-50644). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-5955 |
|
SQL Injection in sqli (CVE-2026-5955)
SQL injection in sqli (CVE-2026-5955). Successful exploitation can lead to full system takeover.
|
| CVE-2026-14342 |
|
SQL Injection in wordpress (CVE-2026-14342)
SQL injection in wordpress (CVE-2026-14342). Confidential information can be exposed externally.
|
| CVE-2026-13011 |
|
SQL Injection in wordpress (CVE-2026-13011)
SQL injection in wordpress (CVE-2026-13011). Confidential information can be exposed externally.
|
| CVE-2026-15135 |
|
Vulnerability in sqli (CVE-2026-15135)
vulnerability in sqli (CVE-2026-15135). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-15137 |
|
Vulnerability in sqli (CVE-2026-15137)
vulnerability in sqli (CVE-2026-15137). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-15134 |
|
Vulnerability in sqli (CVE-2026-15134)
vulnerability in sqli (CVE-2026-15134). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-39178 |
|
SQL Injection in sqli (CVE-2026-39178)
SQL injection in sqli (CVE-2026-39178). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-39179 |
|
SQL Injection in sqli (CVE-2026-39179)
SQL injection in sqli (CVE-2026-39179). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-9074 |
|
SQL Injection in sqli (CVE-2026-9074)
SQL injection in sqli (CVE-2026-9074). Confidential information can be exposed externally.
|
| CVE-2026-15067 |
|
SQL Injection in sqli (CVE-2026-15067)
SQL injection in sqli (CVE-2026-15067). Successful exploitation can lead to full system takeover.
|
| CVE-2026-15062 |
|
SQL Injection in sqli (CVE-2026-15062)
SQL injection in sqli (CVE-2026-15062). Confidential information can be exposed externally.
|
| CVE-2026-59257 |
|
SQL Injection in n8n (CVE-2026-59257)
SQL injection in n8n (CVE-2026-59257). Successful exploitation can lead to full system takeover. Exploitable via ``executeQuery``. Mitigation: upgrade to `2.27.4` or later.
|
| CVE-2026-8307 |
|
SQL Injection in sqli (CVE-2026-8307)
SQL injection in sqli (CVE-2026-8307). Successful exploitation can lead to full system takeover.
|
| CVE-2026-6854 |
|
SQL Injection in wordpress (CVE-2026-6854)
SQL injection in wordpress (CVE-2026-6854). Confidential information can be exposed externally.
|
| CVE-2026-6230 |
|
SQL Injection in wordpress (CVE-2026-6230)
SQL injection in wordpress (CVE-2026-6230). Confidential information can be exposed externally.
|
| CVE-2026-12936 |
|
SQL Injection in wordpress (CVE-2026-12936)
SQL injection in wordpress (CVE-2026-12936). Confidential information can be exposed externally.
|
| CVE-2026-9700 |
|
SQL Injection in wordpress (CVE-2026-9700)
SQL injection in wordpress (CVE-2026-9700). Confidential information can be exposed externally.
|
| CVE-2026-53572 |
|
Vulnerability in github.com/kedacore/keda/v2 (CVE-2026-53572)
vulnerability in github.com/kedacore/keda/v2 (CVE-2026-53572). Confidential information can be exposed externally. Exploitable via ``host``. Mitigation: upgrade to `2.20.0` or later.
|